pam_faillock.so

Andreas Hasenack andreas at canonical.com
Wed May 17 12:42:23 UTC 2023


Hi Leroy,

On Tue, May 16, 2023 at 5:24 PM Leroy Tennison <leroy.tennison at verizon.net>
wrote:

> We are having a miserable experience with pam_faillock.  Have implemented
> on 18 virtual machines (all Ubuntu 22.04).  Logging in from ssh works fine,
> logging in via "virsh console <VM name>" or virt-manager only 12 of the 18
> work.  Getting authentication failures.  The man pages don't show any
> contact information, can you help with this?
>

You will have to post more information about this problem in order for
someone to help you with this, like your pam configuration for this module,
the stack that is active for each of these logins (ssh, and login [for
virsh console I believe]), and the system logs showing the failure (and
successes).


> I notice that pam_tally2.so is still available via snap, is there any
> reason it can't be used with Ubuntu 22?
>

I don't think it's a good candidate for a snap, and am not sure where you
saw that it's available as a snap.

I do seem to remember that both pam_tally and pam_tally2 were indeed
deprecated in favor of pam_faillog, I just can't find the deprecation
notice right now.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/ubuntu-server/attachments/20230517/13b06479/attachment.html>


More information about the ubuntu-server mailing list